Features
Identity & Access Management Service (IAMS) module provides the following features:
AuthenticationSingle-Sign OnandSingle-Sign Out- OpenID Connect a.k.a.
OIDCSupport - Web browser
loginandlogoutsupport - Identity Brokering
- Authenticate with external
OIDCorSAMLIdentity Providers.
- Authenticate with external
- Sync users from
LDAPandActive Directoryservers - Two-factor Authentication (
2FA)- Support for TOTP/HOTP via Google Authenticator or FreeOTP.
Multi-tenancysupport- Authorization
- Role-based access control (RBAC)
- Group-based access control (GBAC)
- User-based access control (UBAC)
IAMS consists of the followings:
- Customized Keycloak (
iams-keycloak) to supportmulti-tenancy - Authorization and Admin Service (IAMS-AAS) that provides APIs to manage authorization access.
- Database to store configurations. The following database types are supported:
- PostgreSQL
- MS SQL
- Oracle